Week in brief

Week of 16 March 2026: Windows passkeys public preview announced; Tenant Governance and bulk operations documented as previews

With 177 of 184 records marked Updated, this was primarily a documentation-maintenance week rather than a broad release wave. The meaningful exceptions are a Message Center notice for phishing-resistant Windows passkeys, three new Microsoft Entra Tenant Governance (preview) pages, and updated guidance for the Entra ID bulk-operations preview. Security documentation also clarifies risk remediation, workload-identity CAE, and Private Access Kerberos and Conditional Access. A second Message Center notice covers unintended disabled draft policies from Baseline Security Mode. No supplied item announces general availability, and the single removed record is not identified well enough to call a retirement.

  • Windows passkeys are announced for a phishing-resistant sign-in public previewEntra ID

    The Microsoft 365 Message Center says Microsoft Entra passkeys on Windows use Windows Hello for phishing-resistant, passwordless sign-in on managed and unmanaged devices. The public preview is stated to run from late March through May 2026. Organizations must opt in and configure passkey policies; existing security policies remain unchanged. This is a public preview notice, not a general-availability release.

  • Tenant Governance gains preview-focused deployment and discovery documentationID Governance

    Three new Microsoft Learn pages cover what Microsoft Entra Tenant Governance is, deployment from setup through tenant discovery, governance, and configuration monitoring, and the signals and metrics used to identify and evaluate related tenants. The Licensing Tenant Governance page was also updated with a comparison covering Free, Microsoft Entra P1, Microsoft Entra P2, and Microsoft Entra ID Governance. The records explicitly label the capability preview; the new pages do not establish a separate launch or general

  • Entra ID bulk operations are described as a preview for large tenantsEntra ID

    Updated guidance says the new bulk operations experience is available in preview for groups, devices, administrative units, and role assignments, with bulk create, update, and delete actions. It is described as improving performance, reducing timeouts, and removing scaling limitations for large tenants. This is documented preview functionality; no general-availability status or required migration is supplied.

  • Updated Conditional Access guidance clarifies risk remediation, workload identities, and Private AccessEntra ID; ID Protection; Workload ID; Private Access

    Updated Microsoft-managed Conditional Access guidance describes MFA-required policies to reduce compromise risk. ID Protection guidance says users with detected risk can self-remediate regardless of whether their method is password-based or passwordless, and the Microsoft-managed remediation control is labeled preview. Workload ID guidance covers enabling Continuous Access Evaluation to enforce Conditional Access and instantly revoke tokens. Private Access updates document Conditional Access for Quick Access and ‍?

  • Baseline Security Mode's unintended draft policies are a corrective noticeEntra ID

    Message Center reports that between November 2025 and February 2026, Baseline Security Mode automatically created two disabled draft Entra Conditional Access policies in some tenants. Microsoft says this was not a security issue and requires no action; a fix will remove the unintended drafts and prevent automatic creation. This is a documented behavior correction, not a new Conditional Access feature.

For Entra administrators

Organizations that want the Windows passkey preview must opt in and configure passkey policies; existing security policies remain unchanged, and the notice identifies no compliance issue. Tenant Governance, bulk operations, and the linked Microsoft-managed risk-remediation control are presented as previews, with no mandatory migration or rollout instruction in the supplied material. The CAE and Private Access updates are relevant when those capabilities are in scope. For the Baseline Security Mode notice, Microsoft says no administrator action is required.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

General

37

Review Recovery History

Updated

If a recovery operation partially succeeds, the **Status** column shows **Completed with warnings**, allowing you to identify objects that weren't recovered. Select **Completed with warnings** to view the details of the changes that were not recovered.

21 March 2026

Prerequisites

Updated

- Nested OUs are supported (that is, you **can** sync an OU that has 130 nested OUs, but you **can't** sync 60 separate OUs in the same configuration).

20 March 2026

Groups Dynamic Rule Member Of

Updated

This feature preview in Microsoft Entra ID enables admins to create dynamic membership groups and administrative units that populate by adding members of other groups using the `memberOf` attribute. Apps that couldn't read group-based membership previously in Microsoft Entra ID can now read the entire membership of these new `memberOf` groups. Not only can these groups be used for apps but they can also be used for licensing assignments.

18 March 2026

Users Bulk Download

Updated

1. Select **Users** > **All users** > **Download users**. By default, all user profiles are exported.

18 March 2026

Groups Dynamic Tutorial

Updated

You're not required to assign licenses to the users for them to be members in dynamic membership groups. You only need the minimum number of available Microsoft Entra ID P1 licenses in the organization to cover all such users.

18 March 2026

Bulk create users in Microsoft Entra ID

Updated

Microsoft Entra ID, part of Microsoft Entra, supports bulk user create and delete operations and supports downloading lists of users. Just fill out the comma-separated values (CSV) template you can download from Microsoft Entra ID.

18 March 2026

Groups Bulk Download

Updated

:::image type="content" source="media/bulk-operations/groups-management-page.png" alt-text="Screenshot of the Microsoft Entra admin center Groups blade showing the All groups list with column headers and actions.":::

18 March 2026

Groups Quickstart Naming Policy

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

18 March 2026

Users Bulk Restore

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

18 March 2026

Groups Bulk Import Members

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Groups Administrator](~/identity/role-based-access-control/permissions-reference.md#groups-administrator).

18 March 2026

Close your work or school account in an unmanaged Microsoft Entra organization

Updated

If you're a user in an unmanaged organization (tenant) in Microsoft Entra ID, and you no longer need to use apps from that organization or maintain any association with it, you can close your account at any time. An unmanaged organization doesn't have an administrator. Users in an unmanaged organization can close their accounts on their own, without contacting an administrator.

18 March 2026

Groups Change Type

Updated

Creating dynamic membership groups eliminates the management overhead of adding and removing users. This article shows you how to convert existing membership groups from static to dynamic, by using either the Azure portal or PowerShell cmdlets. In Microsoft Entra, a single tenant can have a maximum of 15,000 dynamic membership groups.

18 March 2026

Groups Members Owners Search

Updated

On the **All groups** page, when you enter a search string, you can toggle between **contains** and **starts with** searches on the **All groups** page only.

18 March 2026

Groups Saasapps

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](~/identity/role-based-access-control/permissions-reference.md#user-administrator).

18 March 2026

Whats New Linux

Updated

This article provides information about the latest updates to Microsoft single sign-on for Linux.

17 March 2026

Fundamentals

31

View Available Backups

Updated

1. Browse to **Backup and recovery**. The **Overview** page shows feature highlights, alerts, and recent activity.

21 March 2026

Whats New

Updated

**Service category:** MFA

21 March 2026

Create New Tenant

Updated

- **Delegated administration**: Select one or more Microsoft Entra built-in roles and assign them to a role assignable security group in the governing tenant. Members of this group can use their governing tenant credentials to sign in to the governed tenant without needing an account in the governed tenant. Each group can have multiple role assignments, and each policy template can have multiple groups defined.

20 March 2026

Application Gallery

Updated

- **Provisioning** - Microsoft Entra ID to SaaS [application provisioning](~/identity/app-provisioning/user-provisioning.md) refers to automatically creating user identities and roles in the SaaS applications that users need access to.

20 March 2026

What is delegated administration?

Updated

Managing permissions for external partners is a key part of your security posture. The administrator portal experience in Microsoft Entra ID, part of Microsoft Entra, now includes capabilities so that an administrator can see the relationships that their Microsoft Entra tenant has with Microsoft Cloud Service Providers (CSP) who can manage the tenant. This permissions model is called delegated administration. This article introduces the Microsoft Entra administrator to the relationship between the old Delegated Admin Permissions (DAP) permission model and the new [Granular Delegated Admin Permissions (GDAP)](/partner-center/gdap-introduction) permission model.

18 March 2026

Certificate Based Authentication Technical Deep Dive

Updated

:::image type="content" border="true" source="./media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png" alt-text="Screenshot that shows how to turn on issuer hints." lightbox="media/concept-certificate-based-authentication-technical-deep-dive/issuer-hints.png":::

18 March 2026

Directory Overview User Model

Updated

You can use groups in Microsoft Entra ID to assign licenses, or deployed enterprise apps, to large numbers of users. You can also use groups to assign all administrator roles except for Microsoft Entra Global Administrator, or you can grant access to external resources, such as SaaS applications or SharePoint sites.

18 March 2026

Associate or add an Azure subscription to your Microsoft Entra tenant

Updated

All Azure subscriptions have a trust relationship with a Microsoft Entra tenant. Subscriptions rely on this tenant (directory) to authenticate and authorize security principals and devices. When a subscription expires, the trusted instance remains, but the security principals lose access to Azure resources. Subscriptions can only trust a single directory while one Microsoft Entra tenant might be trusted by multiple subscriptions.

17 March 2026

Licensing

Updated

This article discusses licensing options for the Microsoft Entra product family. It's intended for security decision makers, identity and network access administrators, and IT professionals who are considering Microsoft Entra solutions for their organizations.

17 March 2026

Define the Group ID

Updated

> A new bulk operations experience is now available in preview that provides enhanced performance and removes scaling limitations for large tenants. For more information, see [Bulk operations in Microsoft Entra ID (Preview)](bulk-operations.md).

17 March 2026

Whats New Overview

Updated

The **Roadmap** tab lists the details of public preview and recent general availability releases in a sortable table. From the table, you can select a release to view the release **Details**, which includes an overview and a link to learn more.

17 March 2026

Manage User Profile Info

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [User Administrator](../identity/role-based-access-control/permissions-reference.md#user-administrator).

17 March 2026

Add Custom Domain

Updated

1. Create your new directory by following the steps in [Create a new tenant for your organization](./create-new-tenant.md#create-a-new-tenant-for-your-organization).

17 March 2026

Reset a user's password

Updated

Administrators can reset a user's password if the user forgets the password, if the user gets locked out, or if the user never received a password.

17 March 2026

Bulk Operations

Updated

The new bulk operations experience in Microsoft Entra ID provides enhanced capabilities for managing **Groups**, **Devices, Administrative Unit and Role assignments.** This service enables bulk actions including create, update, and delete operations. The improved service delivers better performance, reduces timeouts, and removes scaling limitations for large tenants.

17 March 2026

How to find your tenant ID

Updated

Instructions about how to find your Microsoft Entra tenant ID for an existing Azure subscription.

17 March 2026

Users Restore

Updated

After you delete a user, the account remains in a suspended state for 30 days. During that 30-day window, the user account can be restored, along with all its properties.

17 March 2026

Create New Tenant

Updated

In this quickstart article, you learn how to create a basic tenant for your organization.

17 March 2026

Try Microsoft Entra Suite

Updated

Welcome to the Microsoft Entra Suite trial user guide. Make the most of your free trial by discovering the robust and comprehensive capabilities of [Microsoft Entra](what-is-entra.md).

17 March 2026

Get Started Premium

Updated

You can purchase and associate Microsoft Entra ID P1 or P2 editions with your Azure subscription. If you need to create a new Azure subscription, you also need to [activate your licensing plan](#activate-your-new-license-plan) and your [Microsoft Entra ID service access](#activate-your-microsoft-entra-id-access). For information about obtaining a free trial, see [Microsoft Entra ID P2 Trial](https://signup.microsoft.com/get-started/signup?products=FAF849AB-BD30-42B2-856C-8F1EDC230CE9).

17 March 2026

Entra Admin Center

Updated

The Microsoft Entra admin center is organized by product. Access the products through the search bar or left-hand menu.

17 March 2026

Identity data storage for Australian and New Zealand customers in Microsoft Entra ID

Updated

Microsoft Entra ID stores identity data in a location chosen based on the address provided by your organization when subscribing to a Microsoft service like Microsoft 365 or Azure. For information on where your Identity Customer Data is stored, review the Microsoft Trust Center section titled [Where is your data located?](https://www.microsoft.com/trustcenter/privacy/where-your-data-is-located).

17 March 2026

Sign up for Microsoft Entra ID

Updated

Discover how to sign up for Microsoft Entra ID and Azure. Start using enterprise cloud services today.

17 March 2026

Provisioning

13

Provision Microsoft Entra ID to Active Directory - Configuration

Updated

The following document will guide you through configuring Microsoft Entra Cloud Sync for provisioning groups from Microsoft Entra ID to Active Directory. If you are looking for information on provisioning from AD to Microsoft Entra ID, see [Configure - Provisioning Active Directory to Microsoft Entra ID using Microsoft Entra Cloud Sync](how-to-configure.md).

20 March 2026

Looop Provisioning Tutorial

Updated

![Screenshot of the Manage options with the Provisioning option called out.](common/provisioning.png)

19 March 2026

Open Text Directory Services Provisioning Tutorial

Updated

1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com) as at least a [Cloud Application Administrator](~/identity/role-based-access-control/permissions-reference.md#cloud-application-administrator).

17 March 2026

Authentication

5

Sharing accounts and credentials

Updated

Learn how to configure shared accounts in Microsoft Entra ID using password-based single sign-on so multiple users can securely access apps without sharing passwords directly.

19 March 2026

Github Tutorial

Updated

* You can use Microsoft My Apps. When you select the GitHub tile in the My Apps, this option redirects to GitHub Sign-on URL. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510).

19 March 2026

Share accounts with Microsoft Entra ID

Updated

In Microsoft Entra ID, part of Microsoft Entra, sometimes organizations need to use a single username and password for multiple people, which often happens in the following cases:

18 March 2026

Developer

4

Add Application Portal Setup Sso

Updated

- Completion of the steps in [Quickstart: Create and assign a user account](add-application-portal-assign-users.md).

20 March 2026

Review Admin Consent Requests

Updated

For instance, if an application is found to be non-compliant with company policies, an administrator might choose to 'Block' it. Conversely, if an application is legitimate but requires further review, the administrator may opt to 'Deny' the request temporarily while seeking more information.

20 March 2026

Groups Naming Policy

Updated

You can use attributes that can help you and your users identify which department, office, or geographic region for which the group was created. For example, if you define your naming policy as `PrefixSuffixNamingRequirement = "GRP [GroupName] [Department]"` and `User's department = Engineering`, then an enforced group name might be `"GRP My Group Engineering."` Supported Microsoft Entra attributes are `\[Department\]`, `\[Company\]`, `\[Office\]`, `\[StateOrProvince\]`, `\[CountryOrRegion\]`, and `\[Title\]`. Unsupported user attributes are treated as fixed strings. An example is `"\[postalCode\]"`. Extension attributes and custom attributes aren't supported.

18 March 2026

Users Revoke Access

Updated

Access tokens and refresh tokens are frequently used with thick client applications, and also used in browser-based applications such as single page apps.

18 March 2026

Microsoft identity platform

4

Microsoft Graph

Updated

To manage custom security attribute assignments for users in your Microsoft Entra organization, you can use PowerShell or Microsoft Graph API. The following examples can be used to manage assignments.

18 March 2026

Tenant inaccessible due to inactivity

Updated

Configured tenants no longer in use might still generate costs for your organization. Making a tenant inaccessible due to inactivity helps reduce unnecessary expenses. This article discusses how to handle an inaccessible tenant, reactivation, and guidance for both administrators and application developers.

17 March 2026

Deactivate an app registration

Updated

Learn how to deactivate an app registration in Microsoft Entra ID to prevent token issuance while preserving application configuration.

17 March 2026

Monitoring

3

Create Review Difference Reports

Updated

1. Go to **Backup and recovery** > **Backups**. Select a backup from the list, and then select **Create difference report**.

21 March 2026

Recover Applications

Updated

After you determine the cause of the changes, validate whether the secrets for applications were impacted. Find changes to application secrets in the audit log. Look for events that indicate the application secret was changed or updated.

21 March 2026

Recover Objects

Updated

1. Go to **Backup and recovery** > **Difference reports**. Select a completed difference report.

21 March 2026

Security

3

Security Store In Entra

Updated

Security Store is embedded in the Microsoft Entra admin center, so you can discover and deploy agents and solutions without leaving your identity management workflow.

21 March 2026

Groups Restore Deleted

Updated

User Administrator and Partner Tier 1 Support | Can restore any deleted Microsoft 365 group or cloud security group except those groups assigned to the Global Administrator role

18 March 2026

Groups Settings Cmdlets

Updated

For more information on how to prevent nonadministrator users from creating security groups, set the `AllowedToCreateSecurityGroups` property to False as described in [Update-MgPolicyAuthorizationPolicy](/powershell/module/microsoft.graph.identity.signins/update-mgpolicyauthorizationpolicy).

18 March 2026

Troubleshooting

3

Troubleshooting

Updated

**If the difference report is running for a long time:**

21 March 2026

Troubleshoot Alerts

Updated

Upon successful onboarding, Domain Services back fills synchronized users and groups with the onboarded custom attribute values. The custom attribute values appear gradually, depending on the size of the tenant. To check the backfill status, go to [Domain Services Health](check-health.md) and verify the **Synchronization with Microsoft Entra ID** monitor timestamp has updated within the last hour.

17 March 2026

Standards

2

Conditional Access

1

Governance

1

Fundamentals

2

Conditional Access Grant

Updated

When user risk is detected, users can self-remediate by completing the appropriate remediation flow, regardless of their authentication method. The Microsoft-managed remediation policy in Conditional Access accommodates all authentication methods, including password-based and passwordless. For more information, see [Require risk remediation with Microsoft-managed remediation (preview)](../../id-protection/concept-identity-protection-policies.md#require-risk-remediation-control-preview).

21 March 2026

Governance

16

Licensing Tenant Governance

Updated

| Feature | Free | Microsoft Entra P1 | Microsoft Entra P2 | Microsoft Entra ID Governance |

20 March 2026

Governance Policy Templates

Updated

- Cross-tenant delegated administration roles - Specify which Microsoft Entra built-in roles users from the governing tenant have in the governed tenant.

20 March 2026

Update Governance Relationship

Updated

This article describes how to update an existing governance relationship between a governing tenant and a governed tenant. You might need to update a governance relationship to add or modify delegated administration roles or multitenant application configurations.

20 March 2026

Create Monitor

Updated

- [Configuration management](configuration-management.md)

20 March 2026

Delegated Administration

Updated

- [Monitor governing tenant admin activity](how-to-monitor-governing-activity.md)

20 March 2026

Enable Tenant Discovery

Updated

- [Review the list of related tenants](related-tenants.md) surfaced by discovery.

20 March 2026

Fundamentals

2

Overview

Updated

- Automatically detect tenants that are related to your tenant based on one or more discovery signals.

20 March 2026

Microsoft identity platform

1

Fundamentals

1

General

1

Clean Up Unmanaged Accounts

Updated

Prior to August 2022, Microsoft Entra B2B supported self-service sign-up for email-verified users. With this feature, users create Microsoft Entra accounts, when they verify email ownership. These accounts were created in unmanaged (or viral) tenants: users created accounts with an organization domain, not under IT team management. Access persists after users leave the organization.

18 March 2026

Provisioning

1

Security

1

Tutorial Configure External Id Web App Firewall

Updated

To enable WAF for protection, configure a WAF policy and associate it with Azure Front Door Premium. Microsoft optimizes Azure Front Door premium for security and manages the rule sets provided by the WAF to protect against common vulnerabilities including cross-site scripting and JavaScript exploits. Additionally, Azure WAF provides rule sets that help protect against malicious bot activity and provide layer 7 DDoS protection for your application.

21 March 2026

Security

3

Conditional Access

1

Fundamentals

1

What is Transport Layer Security Inspection?

Updated

The Transport Layer Security (TLS) protocol uses certificates at the transport layer to ensure the privacy, integrity, and authenticity of data exchanged between two communicating parties. While TLS secures legitimate traffic, malicious traffic like malware and data leakage attacks can still hide behind encryption. The Microsoft Entra Internet Access TLS inspection capability provides visibility into encrypted traffic by making content available for enhanced protection, such as malware detection, data loss prevention, prompt inspection, and other advanced security controls. This article gives an overview of the TLS inspection process.

17 March 2026

General

1

Configure Microsoft and Zscaler for a Unified SASE Solution

Updated

Learn how to deploy Microsoft Global Secure Access alongside Zscaler Private Access and Internet Access. Covers four integration scenarios with step-by-step configuration, verification, and traffic testing procedures.

19 March 2026

Troubleshooting

1

How to use enriched Microsoft 365 logs

Updated

View performance, experience, and availability insights for Microsoft 365 apps routed through Microsoft Entra Internet Access. Integrate enriched log data with Log Analytics or Microsoft Sentinel for network diagnostics and security analysis.

19 March 2026

General

4

How to Manage the Private Access Profile

Updated

Configure the Private Access traffic forwarding profile to provide secure, VPN-less access to internal resources through Global Secure Access.

19 March 2026

Authentication

2

Developer

2

Conditional Access

1

Security

9

Verifiable credentials admin API

Updated

The Microsoft Entra Verified ID Admin API enables you to manage all aspects of the Verifiable Credential service. It offers a way to set up a brand new service, manage and create Verifiable Credential contracts, revoke Verifiable Credentials, and completely opt out of the service.

17 March 2026

Plan Verification Solution

Updated

Microsoft’s Microsoft Entra Verified ID (Microsoft Entra VC) service enables you to trust proofs of user identity without expanding your trust boundary. With Microsoft Entra VC, you create accounts or federate with another identity provider. When a solution implements a verification exchange using verifiable credentials, it enables applications to request credentials that aren't bound to a specific domain. This approach makes it easier to request and verify credentials at scale.

17 March 2026

General

3

Whats New

Updated

- Entra Verified ID is supported on Microsoft GCC environments.

17 March 2026

Architecture

1

Authentication

1

Developer

1

Fundamentals

1

Fundamentals

2

What Is Entra

Updated

**For example**, GitHub Actions need a workload identity to access Azure subscriptions to automate, customize, and execute software development workflows.

17 March 2026

Developer

1

Scope Supported Objects Limitations

Updated

An app role assignment records when a user, group, or service principal is assigned an app role for an app. All properties of app role assignment are in scope. View all app role assignment details and properties in the [Microsoft Graph appRoleAssignment resource type](/graph/api/resources/approleassignment).

21 March 2026

Troubleshooting

6

General

5

How to Enable and Manage the Microsoft Profile

Updated

Enable the Microsoft traffic forwarding profile to route traffic to Microsoft 365 services including Exchange Online, SharePoint, and OneDrive through Global Secure Access.

19 March 2026

Microsoft identity platform

3

How to use the remote network health logs

Updated

Access and analyze IPsec tunnel and BGP health logs for remote networks using the Microsoft Entra admin center, Microsoft Graph API, or Log Analytics.

19 March 2026

Security

2

Architecture

1